Orbi WiFi 7 RBE973
Reply

Network flooding from ReadyNAS Pro 6

GUDECO_IT
Aspirant

Network flooding from ReadyNAS Pro 6

Hello there!

We are using a ReadyNAS Pro 6 in our company. But today it suddenly decided to go haywire.

It flooded our network with more than 60.000 Sessions, all to chinese ip addresses. Does anyone here experienced a similar problem? We had the same problem a year ago with another Netgear NAS but solved it by just denying internet access for this specific NAS.

 

I tried to analyse the problem we experienced today:

Looking at the firewall logfiles it started up to 10 unique connections a second to only one ip address (43.227.183.37) which eventually exhausted the NAT port on our firewall, disconnecting our remote offices and vpn users.

We tried to check the logfiles from the NAS itself but there is no reference about massive network-flooding actions.

Does anyone have any idea what the hell happened there? Keep in mind that the connections were started by the NAS itself which is especially fascinating.

Model: ReadyNAS RNDP6000|ReadyNAS Pro 6 Chassis only
Message 1 of 7

Accepted Solutions
StephenB
Guru

Re: Network flooding from ReadyNAS Pro 6


@GUDECO_IT wrote:

 

It was not another NAS that made the same problems a year ago, ... It's almost like a haunted device.


 

Shell-in-the-box could be the vector, especially if web access over the internet is possible.  

 

View solution in original post

Message 4 of 7

All Replies
StephenB
Guru

Re: Network flooding from ReadyNAS Pro 6

What firmware is this NAS running?

what apps (if any) are running on it?

Is access to the NAS over the internet allowed?

 

In general, if the NAS has been compromised then I suggest doing a factory reset, rebuilding the configuration, and then restoring data from backup.

Message 2 of 7
GUDECO_IT
Aspirant

Re: Network flooding from ReadyNAS Pro 6

Thanks for your quick answer.

The NAS runs firmware version 6.10.0 (RC2)

Enabled Apps are:

- Shell in a box (1.0.0)

- SMB Plus (1.0.8)

- Tftp Server for Readynas (1.0.3)

 

The internet access was cut off around 4 hours ago via firewall policy.

Resetting the device is currently not an option because we first have to move something around 3TB of data.

 

But I just got new intel from my colleague:

It was not another NAS that made the same problems a year ago, it was this very NAS. And it was resetted a year ago. It's almost like a haunted device.

Message 3 of 7
StephenB
Guru

Re: Network flooding from ReadyNAS Pro 6


@GUDECO_IT wrote:

 

It was not another NAS that made the same problems a year ago, ... It's almost like a haunted device.


 

Shell-in-the-box could be the vector, especially if web access over the internet is possible.  

 

Message 4 of 7
GUDECO_IT
Aspirant

Re: Network flooding from ReadyNAS Pro 6

Thank you again for your quick answer 🙂

We deactivated and deleted the SIAB app and enabled internet access (for test purposes).

But again the NAS started what almost looks like a DDOS attack against the same IP and created about 100 mbps outbound traffic.

 

After rebooting the NAS it now starts around 1000 sessions to a chinese DNS server (114.114.114.114), the Google 8.8.8.8 and the Google 8.8.4.4 DNS server but NOT to the IP address mentioned in my first post so disabling and deleting the app solved about 90% of our problem 🙂

After disabling the internet access again and ending the sessions in the firewall it went back to normal.

Next step would be the factory reset which we will try to do maybe as early as this week.

Message 5 of 7
Hopchen
Prodigy

Re: Network flooding from ReadyNAS Pro 6

I will 100% agree with @StephenB so it is good that you are going to factory reset it.

Make sure your passwords are strong. I am talking like 20 digits randomly generated passwords. Don't open the NAS to the Internet (port forwarding) unless it is absolutely crucial to the workflow. If people need to access the NAS CLI then use Putty and SSH. I would also advise to turn off HTTP admin so the admin page can only be accessed via HTTPS.

 

But again, use strong passwords! 🙂

Message 6 of 7
GUDECO_IT
Aspirant

Re: Network flooding from ReadyNAS Pro 6

And again thanks for the support!

We changed the password to a 25 digit random upper-lower-syntaxerror password.

So I guess I witnessed my first infected (possessed) device in my career 🙂

 

I will mark the thread as resolved since the factory reset will be somewhere in the future.

Thank you!

Message 7 of 7
Top Contributors
Discussion stats
  • 6 replies
  • 2629 views
  • 0 kudos
  • 3 in conversation
Announcements